Internet Security Tool
betterinternetbureau.net

Internet Security Tool - Logo

Internet Security Tool Main

Internet Security Tool Home
Internet Security Tool RSS/News
Internet Security Tips

Internet Security Tool RSS/News

Internet Security Reports

First impressions are lasting! Place the Better Internet Bureau seal of approval on your Web site!

Internet Security Tool - Image

New Internet Security Tool helps you create a professional privacy policy in ten minutes! It's easy!
www.privacyaffiliates.com 

Internet Security Tool - Logo

Automated Analysis of Security-Sensitive Protocols

The sheer number and variety of security protocols for Internet applications under development makes it difficult to be sure that any one protocol is 100 per cent secure from attack. Now an automated tool can systematically validate these security-sensitive protocols and applications.

The sheer number and variety of security protocols for Internet applications under development makes it difficult to be sure that any one protocol is 100 per cent secure from attack. Now an automated tool can systematically validate these security-sensitive protocols and applications.



“The AVISPA software tool enables a security protocol designer to input the protocol and the language he/she wishes to use, then feeds back information on this protocol including any known bugs or security weaknesses,” says Professor Alessandro Armando of the University of Genoa’s Artificial Intelligence Laboratory (DIST) and coordinator of the IST programme-backed Future and Emerging Technologies project AVISPA. “Previously such protocol designers had no automated support to help them in their design role – that is the purpose of the AVISPA tool."

Secure protocols are a vital element in carrying out safe online interactions between a user’s Web browser and a company Web server, for example a bank’s Web server in an online banking application. Though such protocols might look simple, they can often be extremely difficult to get absolutely right, such as with no bugs or weaknesses in the protocol.

Armando quotes the classic example of the Needham-Schroeder public-key protocol, which was first published in 1978 as a means of mutual authentication between two parties using public-key cryptography. The protocol was eventually found to be vulnerable to simple attacks in 1996, eighteen years later!

AVISPA participants aimed to develop a push-button, industrial-strength technology for the analysis of such security-sensitive Internet protocols and applications. The project finished in July 2005 with the release of the AVISPA tool, which is a simple software application that runs on a PC or via a Web interface. It can be accessed online, and offers both a Basic and an Expert mode.

The consortium partners believe that this new tool will help speed the development of the next generation of security protocols, and improve their security in the process.

Project partner Siemens has already discovered a weakness in one of its own protocols using the tool, and has revised the protocol and issued a new patent accordingly. The partners have also been joined by SAP and submitted the AVISPA results for inclusion into a potential new IST project AVACOSS which will analyse more complex security-sensitive applications. 

For more information contact Tara Morris at Ist Results
http://istresults.cordis.lu


City of Montreal Awards Managed IT Security Services Contract to Above Security
Above Security has been awarded a three-year contract by the City of Montreal covering the installation of a security infrastructure solution, as well as the monitoring of the City’s most critical...
Virtual Machines - Rapid Security Tool Deployment
You may reprint or publish this article free of charge as long as
the bylines are included.

Original URL (The Web version of the article)
------------
http://www.defendingthenet.com/NewsLetters/Virt...
Special Ops Security Releases Sqlrecon V1.0 Free Database Scanning Tool
Chip Andrews of SQL Server Security fame and now a founder of Special Ops Security, has completed work on the successor to SQLPing2 which aggregates multiple SQL Server discovery methods into a single,...
Secure-It™ Protects Against Various Windows Vulnerabilities Including some Not Patched by Microsoft
Secure-It™ 1.2 is a free local Windows security hardening tool, proactively secure your PC by either disabling the intrusion and propagation vectors proactively or simply reduce the attack surface by disabling...
Webfargo Data Security Announces Launch of the Webfargo Security Center
Webfargo Data Security, LLC, the Triangles only locally owned provider specializing in managed security services, announced today the launch of The Webfargo Security Center, the companys client-only...
HNS Consulting Announces the First Issue of (IN)SECURE Magazine
HNS Consulting Ltd. today announced the first issue of (IN)SECURE Magazine, a freely available, freely distributable digital security magazine discussing some of the hottest information security topics....
Securing your Computer to Keep Up with Internet Threats
When spyware invades a computer system it monitors, records and sends out to intruders information on your computer usage and internet habits and it can possibly detect private banking and security information...
Security Audit Resources Now Includes Security Audit Companies
Finding an Information security consultant is as difficult as understanding the problems of software. Computer Security 4Terrorism is working to provide businesses large and small with information security...
Application Security - IT Risk Management
Application Security risk assessment and risk management are vital tasks for IT managers. Corporations face increased levels of Application Security risk from hackers and cyber crooks seeking intellectual...
Internet network security policies need a radical rethink!
Data-recovery-reviews.com,the leading portal on data storage, data recovery and network security has suggested that internet network security policies that deal with organization wide internet security...
New Tool From Syhunt Helps Organizations Secure Their Web Applications
Syhunt Collapse allows web administrators to identify and mitigate thousands of potential vulnerabilities and misconfigurations (PRWEB) August 10, 2005 - Syhunt Security today unveiled the Collapse software,...
A Tool to Unlock the Secrets of Strong Computer Security
Think Computer Security is complex? At last a system hardening tool that puts Computer Security in the hands of the user. (PRWEB) March 28, 2005 -- The Computer Security Tool by GetData Software Company...
UK Security Directory Launched
Bringing the latest security news from the UK and around the world, the UK Security Directory is a source for news as well as product updates and industry announcements. (PRWEB) August 24, 2005 -- The...
Authentium Acquires Leading Desktop Security Technology
Leading security software integrator acquires leading desktop security technology; Authentium Extensible Security Platform network expands to include 25,000 schools, millions of student desktops. West...
Backup Security Blunders Continue; Security Experts Offer Effective Solutions
Corporate data used to be an easy and elegant component of IT management. Now it has become one of the biggest security risks in the business. Toronto security consultants expose the risks and offer solutions...
IntraSource Expands Managed Security Service Partnership With ProtectPoint Security, Inc. enhances Security Suite
IntraSource, Inc. a Kentucky based Information Technology firm providing business solutions and professional IT Services has expanded its BusinessNET Managed Service offerings to include a new Managed...
iVolution to Offer Comprehensive Managed Security Services
Partnership with ProtectPoint Security, Inc. enhances Security Suite. iVolution Technologies, Inc., a leading Training and Security Services Company, has now added the comprehensive Managed Security Solution...
The New Directory of Network Security
(PRWEB) September 25, 2005 -- Finding an Information security consultant is as difficult as understanding the problems of software and networks. ATM Network Security is working to provide businesses large...
Above Security Launches its CSC2 Security Information Management System
Above Security announces the general availability of its CSC2 Security Information Management (SIM) system—the industrys first completely integrate, end-to-end system that bundles both the intrusion and...
Beyond-Security Now CVE Compatible
Beyond-IP delivers vendor-neutral framework for describing security vulnerabilities Northbrook, IL (PRWEB) March 27, 2005 -- Beyond Security (www.beyondsecurity.com) announced their Security Assessment...
Learn Security Online Announces New Training Methods
Formerly RootWars.org - a website purely focused on hacking competitions is now back after a complete make-over as LearnSecurityOnline.com using simulators, security games, and challenge servers to teach...
New Service Exposes the Industry Behind Computer Security
Controversial "Whisper" Update threatens to pull no punches in its coverage of the industry behind computer security WOONSOCKET, RI (PRWEB) February 2, 2005 -- Vmyths.com has launched a new "Whisper" Update...